Privacy Policy
Last updated 12 June 2026
IRL Social (“IRL Social”, “we”, “us”) helps you see who you crossed paths with during the day. Privacy is the core of the product: we are built to know as little as possible about where you are. This policy explains what we collect, why, how long we keep it, and the choices you have.
Who we are
IRL Social is operated by the IRL Social team. For privacy questions or requests, contact michaljach@gmail.com.
What we collect
- Coarse, fuzzed location. We never store your precise coordinates. On your device, your location is reduced to a roughly 150-metre grid cell plus a coarse time bucket, with an anti-stalking offset applied, before anything is sent to us. We cannot reconstruct your exact location or route from what we store.
- Bluetooth proximity signals. When the app is running we broadcast and read a rotating, anonymous token over Bluetooth to confirm two devices were physically near each other. The token rotates over time and is not a permanent identifier.
- Your pseudonymous profile. A handle, emoji, accent colour, optional short bio, optional display name, and an optional avatar photo.
- Content you create. Photos and videos you add to your profile, send in chats, or post as stories; the text of your messages; story likes and views.
- Account identity. When you use Sign in with Apple, we receive a Cognito user identifier (and the Apple relay email if you choose to share it). We do not receive your real Apple ID password or contacts.
- Basic operational data. Minimal logs needed to run and secure the service.
We do not sell your data, and we do not use it for third-party advertising or cross-app tracking.
How we use it
- To detect, privately, when you and another person crossed paths and to show you pseudonymous “encounter” cards.
- To let you connect with, message, and share stories with people you choose.
- To keep the service secure and to handle abuse reports and blocks.
What others can see
Until both people choose to connect, another user only ever sees your pseudonymous identity (handle, emoji, accent colour) on an encounter — never your name or precise location. Your real display name is shown only to people you have mutually connected with. Story views and likes are visible only to the person who posted the story.
How long we keep it
- Presence pings and encounters auto-delete after 24 hours (enforced by database time-to-live). Your “trail” expires on its own.
- Stories expire after 24 hours.
- Profile, connections, and chat messages persist until you delete them or delete your account.
Where it is processed
IRL Social runs on Amazon Web Services (Cognito, AppSync, DynamoDB, Lambda, S3) in the United States. AWS processes data on our behalf as a service provider.
Your choices and rights
- Pause sharing. Stop uploading presence and Bluetooth signals at any time in Settings, without signing out.
- Block and report. Block any user to hide their content from you, and report content that violates our Terms.
- Delete your account. Settings → Delete account permanently deletes your account and removes your profile, stories, and avatar. Pseudonymous, denormalised snapshots held by people you connected with may persist on their side.
- Access/Erasure requests. Email michaljach@gmail.com.
Permissions we request
- Location (“Always”). Required so the app can notice cross-paths events in the background. Only the fuzzed cell described above ever leaves your device.
- Bluetooth. Used for the anonymous proximity token exchange.
- Photos. Used only when you pick media to share.
Children
IRL Social is not directed to children under 13 and you must meet the minimum age in your jurisdiction (and at least 17, the app's age rating) to use it.
Changes
We will update this policy as the product changes and revise the “Last updated” date above.
Contact
michaljach@gmail.com